Obligations

Company obligations under the EU AI Act

Regulation (EU) 2024/1689 on artificial intelligence imposes concrete obligations not only on technology makers, but also on ordinary companies that merely use artificial intelligence. This guide explains which role you fall into, what the law requires of you exactly, and from when.

Roles under the AI Act

The regulation distinguishes four core roles and expects different obligations from each. The first step towards compliance is finding out which role your company falls into, or whether it holds more than one role at once.

Provider

Whoever develops an AI system or places it on the Union market under their own name. Carries the strictest obligations, including technical documentation and conformity assessment.

Deployer

Whoever uses an AI system in the course of their business. The vast majority of companies that merely put AI to work fall into this role.

Importer

Whoever places an AI system from a provider established outside the EU on the Union market. Verifies that the system meets the regulation's requirements.

Distributor

Whoever makes an AI system available on the market but is neither the provider nor the importer. Chiefly checks the marking and accompanying documentation.

Most companies are deployers

If your company does not develop artificial intelligence itself but merely uses it, you are a deployer. This applies, for example, to using the ChatGPT tool to draft texts, deploying software to pre-screen CVs in the HR department, a chatbot in customer support, or a system that assesses the creditworthiness of clients. This role matters most to small and medium-sized businesses, because the obligations apply even to those who did not build the technology but only put it into operation.

The scope of your obligations depends on which risk category the system falls into. That is why we recommend starting with the risk classification — this tells you whether the system carries unacceptable, high, limited or minimal risk, and the specific obligations follow from there. A single company can hold different roles towards different tools: with an ordinary office tool it is a deployer, but if it fine-tuned that same model and offered it on under its own brand, it becomes a provider with all the stricter obligations. That is why it is important to assess each system on its own, rather than the company as a whole.

Deployer obligations

AI literacy of staff (Art. 4, applies from 2 Feb 2025)

The company must ensure a sufficient level of AI knowledge among employees and other persons who work with AI on its behalf. In practice this means training appropriate to the person's role, their education and the context in which they use the system. This obligation applies first, from 2 February 2025, and concerns practically every company that deploys AI.

Transparency and labelling of AI content (Art. 50, from 2 Aug 2026)

If you communicate with customers through a chatbot, you must inform them that they are talking to an AI system. Artificially generated or manipulated images, audio or video (deepfakes), and text published to inform the public, must be visibly marked. This obligation applies from 2 August 2026. For machine-readable labelling under Article 50(2) a transitional period runs until 2 December 2026, but only for systems placed on the market before 2 August 2026; systems placed later had to label from day one.

Fundamental Rights Impact Assessment — FRIA (Art. 27)

For certain high-risk systems, the deployer must carry out a Fundamental Rights Impact Assessment before deployment. It evaluates how the system may affect the rights of the people concerned and what measures mitigate the risks.

Human oversight (Art. 14)

High-risk systems must be deployed so that effective human oversight is ensured. The designated person must understand the system's outputs, be able to reassess them and, if needed, intervene or stop operation.

Registration of certain systems in the EU database (Art. 49)

Selected high-risk systems are registered in a public Union database before being put into service. A deployer that is a public authority has a separate registration duty for some systems.

Use according to instructions and monitoring of operation

The deployer must use the system in line with the provider's instructions, monitor its functioning and keep the automatically generated records (logs). If it detects a serious risk or incident, it must inform the provider and the relevant supervisory authority without undue delay.

Provider obligations

The provider carries the bulk of the obligations. For high-risk systems it must draw up technical documentation, put in place risk-management and quality-management systems, ensure the quality of input data, carry out a conformity assessment and affix the CE marking. If you develop or place AI on the market under your own brand, you will find the exact scope of obligations and their timing in the overview of deadlines and the timeline.

What non-compliance risks

The regulation introduces tangible penalties. Using prohibited practices carries the highest fines, while breaching the other obligations carries lower but still significant amounts based on worldwide turnover. You will find a detailed overview of the penalty amounts on the page about fines.

How to meet your obligations

Proceed systematically: draw up a list of all the AI systems you use in the company, determine your role and risk category for each, arrange AI-literacy training for staff, set rules for transparency and human oversight, and document the whole process. Regulation (EU) 2024/1689 has applied since 1 August 2024; Regulation (EU) 2026/1744 (the Digital Omnibus on AI) moved the application of standalone high-risk systems under Annex III to 2 December 2027. The transparency obligations under Article 50 have applied since 2 August 2026, and AI literacy under Article 4 since 2 February 2025. Start with what applies earliest — AI literacy.

Not sure where to start? The free check shows you within minutes which role you fall into, which systems are risky and which obligations apply to you.

How AiComply complies with Article 50

AiComply follows the same rules it recommends to companies. In line with Article 50, the chatbot on this page is visibly identified as artificial intelligence — in its opening message it introduces itself as an automated AI assistant, and the window header carries a permanent "Automated AI assistant" label. Users always know they are talking to a machine, not a person.

A practical example: This is exactly the kind of visible chatbot labelling that Article 50 requires from every company deploying AI in customer contact — from 2 August 2026.

This content is informational and does not constitute legal advice. It is based on Regulation (EU) 2024/1689. For a binding assessment of your situation, consult a qualified professional.

AiComply asistent Automatizovaný AI asistent
EU AI Act
Dobrý deň! Som AiComply asistent — automatizovaný chatbot s umelou inteligenciou. Poradím vám s EU AI Act a súladom. Čo vás zaujíma? Spustiť bezplatnú kontrolu